
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58944 is a Local File Inclusion (LFI) vulnerability in the axiomthemes Manufactory WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Manufactory theme up to and including version 1.4, and allows unauthenticated network attackers to include arbitrary local files from the server. The vulnerability was reported by security researcher "Bonds" on August 3, 2025, and published by Patchstack on September 2, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the Manufactory theme (CWE-98), which allows user-supplied input to influence which local file is included and executed. An unauthenticated remote attacker can craft a malicious HTTP request that manipulates a filename parameter to traverse the file system and include sensitive local files, causing their contents to be rendered in the server response. No user interaction is required, though the attack complexity is rated High, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. Exposure of database credentials could lead to complete database takeover, unauthorized data access, and potential full site compromise. The vulnerability also poses risks to confidentiality, integrity, and availability, as rated High across all three impact categories in the CVSS score (Patchstack).
No public proof-of-concept exploit code has been published, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The vulnerability requires no authentication or user interaction, making it attractive for mass-exploit campaigns targeting WordPress sites at scale, as noted by Patchstack. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
/wp-content/themes/manufactory/style.css).include/require statement without proper sanitization.../../../../wp-config.php) in the filename parameter.wp-config.php with database credentials, /etc/passwd, or other sensitive server files).../, ..%2F, ....//) in query parameters or POST body; repeated requests from a single IP to theme-related PHP files.wp-config, passwd, or other sensitive file names in parameters.wp-config.php, /etc/passwd, or other sensitive files by the web server process.As of the time of publication, no official patch from the theme developer (axiomthemes) is available for the Manufactory theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners should consider replacing or disabling the theme if an upgrade path is unavailable, implementing web application firewall (WAF) rules to block path traversal patterns, and restricting network-level access to the WordPress installation where possible. Monitoring server logs for suspicious file inclusion attempts is also recommended (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher "Bonds," has classified it as high priority and noted that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites. No significant vendor statements from axiomthemes or broader media coverage have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."